VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,116)

page 104 of 156
  • CVE-2025-1403HigFeb 21, 2025
    risk 0.49cvss 8.6epss 0.01

    Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.

  • CVE-2024-57762HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.01

    MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.

  • CVE-2024-20150HigJan 6, 2025
    risk 0.49cvss 7.5epss 0.01

    In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01412526; Issue ID: MSV-2018.

  • CVE-2024-56068HigDec 31, 2024
    risk 0.49cvss 7.5epss 0.00

    Deserialization of Untrusted Data vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

  • CVE-2024-11839HigDec 13, 2024
    risk 0.49cvss 7.5epss 0.00

    Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-10382HigNov 20, 2024
    risk 0.49cvss 7.5epss 0.00

    There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction of arbitrary java classes. This can lead to arbitrary code execution when combined with specific Java deserialization gadgets. An…

  • CVE-2024-6960HigJul 21, 2024
    risk 0.49cvss 7.5epss 0.01

    The H2O machine learning platform uses "Iced" classes as the primary means of moving Java Objects around the cluster. The Iced format supports inclusion of serialized Java objects. When a model is deserialized, any class is allowed to be deserialized (no class whitelist). An…

  • CVE-2024-5016HigJun 25, 2024
    risk 0.49cvss 7.2epss 0.22

    In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM.  The vulnerability exists in the main message processing routines NmDistributed.DistributedServic…

  • CVE-2024-31879HigMay 18, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539.

  • CVE-2024-34997HigMay 17, 2024
    risk 0.49cvss 7.5epss 0.01

    joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching of trusted content.

  • CVE-2024-4733HigMay 16, 2024
    risk 0.49cvss 7.5epss 0.01

    The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the `hc3_session`-cookie in versions up to, and including, 4.9.57. This makes it possible for an authenticated attacker with contributor…

  • CVE-2024-4838HigMay 16, 2024
    risk 0.49cvss 7.5epss 0.01

    The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated…

  • CVE-2024-3967HigMay 15, 2024
    risk 0.49cvss 7.6epss 0.01

    Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.

  • CVE-2024-1897HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.01

    The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization via shortcode of untrusted input from the awl_gg_settings_ meta value. This makes it possible for…

  • CVE-2024-1896HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.01

    The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.2 via deserialization via shortcode of untrusted input from the…

  • CVE-2024-2501HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.01

    The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.33.1 via deserialization of untrusted input via the 'dpsp_maybe_unserialize' function. This makes it possible for…

  • CVE-2024-1951HigMar 13, 2024
    risk 0.49cvss 7.5epss 0.01

    The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8 via deserialization via shortcode of untrusted input. This makes it possible for authenticated attackers,…

  • CVE-2024-1950HigMar 13, 2024
    risk 0.49cvss 7.5epss 0.01

    The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted input via shortcode. This makes it possible for authenticated attackers, with…

  • CVE-2023-52357HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of serialization/deserialization mismatch in the vibration framework.Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-24926HigFeb 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.